Business Associate Agreements: What Administrators Must Check

Few HIPAA documents are as widely signed and as rarely read as the business associate agreement, or BAA. Yet it is the contract that governs how an outside company may use and protect resident information on your behalf. When a vendor has a breach, the BAA often determines who must notify whom, how quickly and who bears responsibility.

This article explains in plain terms who needs a BAA, what it should include and what administrators should verify.

Who Counts as a Business Associate

Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides certain services to it involving that information. Examples in a long-term care setting commonly include:

EHR and clinical software vendors

Managed IT service providers with access to systems holding PHI

Cloud hosting and backup providers

Billing and revenue cycle companies

Consulting, legal and accounting firms that see PHI

Shredding and records storage companies

eFax and email service providers handling PHI

Telehealth platforms

Some relationships are a gray area. HHS has said that a cloud provider that stores encrypted PHI is a business associate even if it does not hold the encryption key. A different example is a janitorial service with incidental exposure, which generally is not a business associate but still needs confidentiality terms. When uncertain, ask your privacy officer or counsel.

What a BAA Must Include

The HIPAA Privacy and Security Rules specify required elements. A compliant BAA generally:

Describes the permitted and required uses and disclosures of PHI

Prohibits any use or disclosure not allowed by the contract or by law

Requires the business associate to use appropriate safeguards and comply with the Security Rule for electronic PHI

Requires the business associate to report to you any use or disclosure not permitted, including security incidents and breaches of unsecured PHI

Requires subcontractors that handle PHI to agree to the same restrictions

Makes PHI available so you can respond to resident requests for access, amendment and an accounting of disclosures

Requires return or destruction of PHI at contract end, when feasible

Allows you to terminate the contract if the business associate violates a material term

What to Look at Beyond the Minimum

Many BAAs are written by the vendor. Before signing, pay attention to:

Breach reporting timeline

The HIPAA Breach Notification Rule requires business associates to notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your own deadlines may start earlier depending on the circumstances, so negotiate a much shorter window in your agreement, such as a few business days for an initial notice.

Subcontractors

Ask which subcontractors will touch your data and where they are located.

Liability and indemnification

Some vendors try to cap liability very low. Consider whether the cap is reasonable for the risk and whether cyber insurance covers gaps.

Data location and return

Confirm that data stays in the United States if that matters to you, and that you can get your data back in a usable format.

Audit rights

See whether you can request security documentation or reports.

Common Gaps Found During Reviews

No BAA at all for a vendor that clearly handles PHI

BAAs signed years ago and never updated after services changed

Missing BAAs for subcontractors or minor tools such as a scanning app

Nobody knows where the signed copies are stored

Expired relationships where the vendor still has access to data

Staff signing up for free online tools with resident information and no agreement

Build a Simple Tracking Process

Maintain a vendor list with columns for vendor name, services, whether PHI is involved, BAA signed date, renewal or review date and an internal owner. Review it annually and whenever a new tool is introduced. Pair it with a rule that staff must consult the privacy or IT lead before adopting any new software that might touch resident data.

Retain BAAs for at least six years, in line with HIPAA's documentation requirements.

Do Not Forget Your Role as a Business Associate

If you provide services to other covered entities, you may be a business associate yourself. In that case you are directly responsible for Security Rule compliance and must sign BAAs with your own subcontractors.

Where to Get Help

HHS publishes sample BAA provisions on its website, which are a useful starting reference. Your attorney should review final agreements. UnityCare IT signs BAAs with healthcare clients and can help you inventory vendors, spot missing agreements and understand the technical safeguards described in them.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172